This program is tentative and subject to change.

Thu 27 Aug 2026 14:24 - 14:42 at IP126 Auditorium - Dependent Types and Proof Chair(s): Sam Westrick

Formal verification of neuro-symbolic cyber-physical systems, such as drones, medical devices and robots, is complicated. Neural components must be trained to be optimal with respect to the available data as well as the safety specifications, and then verified using specialised solvers. Symbolic models of the “cyber” and “physical” behaviour of the system must be constructed and verified in interactive theorem provers (ITPs), often requiring mature mathematical libraries to reason about the interplay of discrete and continuous dynamics, preferably obtaining infinite time-horizon guarantees. Finally, the results of the two already challenging verification tasks need to be integrated into a single proof in a coherent and consistent way, whilst preserving deployability of the resulting model.

In this paper we present a compositional methodology for constructing such proofs. The Vehicle framework provides a functional, domain-specific language for specifying, training, and verifying neural components. We extend Vehicle to allow integration with any ITP with minimal effort, thereby bridging the gap between the neural and symbolic proofs. First, we describe how Vehicle’s standard bidirectional type checker can be reused to transpile neural specifications into an intermediate representation targeting multiple theorem provers. Second, we integrate Vehicle with Rocq, Isabelle/HOL, Agda and the industrial prover Imandra; and showcase a generic infinite time-horizon safety proof of a discrete cyber-physical system with a neural network controller in each ITP. Finally, to put the idea of compositional neural-cyber-physical system verification to the test, we use the Mathematical Components libraries in Rocq to verify infinite time-horizon safety of a medical device, modelled as a continuous cyber-physical system with a neural controller. To our knowledge, this is the first result of this kind in a general purpose ITP; and a result that was only feasible thanks to the compositionality provided by Vehicle’s functional interface.

This program is tentative and subject to change.

Thu 27 Aug

Displayed time zone: Eastern Time (US & Canada) change

13:30 - 15:00
Dependent Types and ProofICFP Papers at IP126 Auditorium
Chair(s): Sam Westrick New York University
13:30
18m
Talk
Confluence Techniques for Dependent Type Theory with Typed ConversionRemote
ICFP Papers
DOI Pre-print
13:48
18m
Talk
An Equational and Graphical Fixed-Point Calculus (Functional Pearl)Remote
ICFP Papers
Gustavo de Mendonça Freire Universidade Federal do Rio de Janeiro, Hugo Musso Gualandi Universidade Federal do Rio de Janeiro, Hugo Nobrega Universidade Federal do Rio de Janeiro, Joao Paixao Universidade Federal do Rio de Janeiro
DOI
14:06
18m
Talk
Citrus: Algebraic Reasoning About Superconductor Electronics
ICFP Papers
Harlan Kringen , Ben Hardekopf University of California at Santa Barbara, Timothy Sherwood University of California at Santa Barbara
DOI
14:24
18m
Talk
Compositional Neural-Cyber-Physical System Verification in the Interactive Theorem Prover of Your Choice
ICFP Papers
Matthew L. Daggitt University of Western Australia, Ekaterina Komendantskaya University of Southampton, Alessandro Bruni IT University of Copenhagen, Samuel Teuber KIT, Alistair Sirman University of Southampton, Grant Passmore Imandra Inc., Josh Smart University of Southampton
DOI
14:42
18m
Talk
Completeness of Iris-Based Program Logics
ICFP Papers
Johannes Hostert ETH Zurich, Zichen Zhang New York University, Puming Liu NYU Shanghai, Simon Oddershede Gregersen CISPA Helmholtz Center for Information Security, Ralf Jung ETH Zurich, Joseph Tassarotti New York University
DOI Pre-print
Hide past events